{ config, lib, pkgs, ... }: with import ; let external-ip = config.krebs.build.host.nets.internet.ip4.addr; ext-if = config.makefu.server.primary-itf; allDisks = [ "/dev/sda" "/dev/sdb" ]; in { imports = [ ./hetznercloud { # wait for mount systemd.services.rtorrent.wantedBy = lib.mkForce []; systemd.services.phpfpm-nextcloud.wantedBy = lib.mkForce []; systemd.services.samba-smbd.wantedBy = lib.mkForce []; } { users.users.lass = { uid = 19002; isNormalUser = true; createHome = true; useDefaultShell = true; openssh.authorizedKeys.keys = with config.krebs.users; [ lass.pubkey makefu.pubkey ]; }; } # # # Security # Tools # # # networking # # # # { # bonus retiolum config for connecting more hosts krebs.tinc.retiolum = { #extraConfig = lib.mkForce '' # ListenAddress = ${external-ip} 53 # ListenAddress = ${external-ip} 655 # ListenAddress = ${external-ip} 21031 # StrictSubnets = yes # LocalDiscovery = no #''; connectTo = [ "prism" "ni" "enklave" "eve" "dishfire" ]; }; networking.firewall = { allowedTCPPorts = [ 53 655 21031 ]; allowedUDPPorts = [ 53 655 21031 ]; }; } # ci # ### systemdUltras ### ###### Shack ##### # # # services # postgres backend # # { krebs.exim.enable = mkDefault true; } # sharing # samba sahre # { nixpkgs.config.allowUnfree = true; } # ## # # # ## network # # { makefu.backup.server.repo = "/var/backup/borg"; } { # recent changes mediawiki bot networking.firewall.allowedUDPPorts = [ 5005 5006 ]; } # Removed until move: no extra mails # # Removed until move: avoid letsencrypt ban ### Web # postgres backend # postgres backend #postgres backend ### Moving owncloud data dir to /media/cloud/nextcloud-data { users.users.nextcloud.extraGroups = [ "download" ]; # nextcloud-setup fails as it cannot set permissions for nextcloud systemd.services.nextcloud-setup.serviceConfig.SuccessExitStatus = "0 1"; systemd.tmpfiles.rules = [ "L /var/lib/nextcloud/data - - - - /media/cloud/nextcloud-data" "L /var/backup - - - - /media/cloud/gum-backup" ]; #fileSystems."/var/lib/nextcloud/data" = { # device = "/media/cloud/nextcloud-data"; # options = [ "bind" ]; #}; #fileSystems."/var/backup" = { # device = "/media/cloud/gum-backup"; # options = [ "bind" ]; #}; } # ## # # # # # # # # # # # # # # # sharing { krebs.airdcpp.dcpp.shares = { download.path = config.makefu.dl-dir + "/finished"; sorted.path = config.makefu.dl-dir + "/sorted"; }; } ## Temporary: # # # # krebs infrastructure services # ]; # makefu.dl-dir = "/var/download"; makefu.dl-dir = "/media/cloud/download/finished"; services.openssh.hostKeys = lib.mkForce [ { bits = 4096; path = (toString ); type = "rsa"; } { path = (toString ); type = "ed25519"; } ]; ###### stable security.acme.certs."cgit.euer.krebsco.de" = { email = "letsencrypt@syntax-fehler.de"; webroot = "/var/lib/acme/acme-challenge"; group = "nginx"; }; services.nginx.virtualHosts."cgit" = { serverAliases = [ "cgit.euer.krebsco.de" ]; addSSL = true; sslCertificate = "/var/lib/acme/cgit.euer.krebsco.de/fullchain.pem"; sslCertificateKey = "/var/lib/acme/cgit.euer.krebsco.de/key.pem"; locations."/.well-known/acme-challenge".extraConfig = '' root /var/lib/acme/acme-challenge; ''; }; krebs.build.host = config.krebs.hosts.gum; # Network networking = { firewall = { allowedTCPPorts = [ 80 443 28967 # storj ]; allowPing = true; logRefusedConnections = false; }; nameservers = [ "8.8.8.8" ]; }; users.users.makefu.extraGroups = [ "download" "nginx" ]; state = [ "/home/makefu/.weechat" ]; }